Analytics BIOC
Low
✕
Azure account deletion by a non-standard account
An Azure AD account deletion was performed by a user that doesn't typically delete users.
- Module:
- Identity Threat Detection (ITDR), SaaS Threat Detection
- Licensed by:
- Identity Threat Detection (ITDR)
- Data source:
- AzureAD Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Account Access Removal (T1531)
Attacker's goals:
Interrupt availability and access to Azure by deleting access accounts.
Investigative actions:
Follow further actions by the initiator. Check what services, groups and applications are affected by the deleted user being removed. Check if the deleted user had a privileged role.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Azure account deletion by a non-standard account with high administrative activity Informational (parent: Low)
- A suspicious Azure account deletion by a non-standard account Medium (parent: Low)